Episode 188: DEFCON 34 Hotel Room Debrief
Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!
Today’s Guests:
====== This Week in Bug Bounty ======
YesWeHack is introducing Credits to combat AI slop reports
https://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits
====== Timestamps ======
(00:00:00) Introduction
(00:03:45) DEFCON Event Reactions and Takeaways
(00:12:56) Bus & Turbo Talk Overviews
(00:21:53) Event Bugs
[00:00:00.78] - Nick Copi
Before I flew out to Vegas, I woke up at like 1 AM. You know, I had to wake up at 6 for my flight. I woke up from a nightmare that I was like HTML being injected into the DOM and I'm being blocked by the CSP and can't execute.
[00:00:35.61] - Ads Dawson
Sup hackers, hope you guys are amped up and ready to hack after all the festivities at DEF CON this past week and all the crazy research as well that dropped. Um, always very inspiring, I think. Uh, so we have an exciting announcement to give you as well. Um, Adobe is going to be shifting their program over to Integritee. Okay, the cutover date is going to be September 1st. So if you're hacking on them, they're going to pause their program, shift over to Integrity. So what we want you to do right now is go register for Integrity if you haven't already. Okay. We're going to put the link in the description to do that. And in order to celebrate this shift with them, Critical Thinking is going to give away a lifetime Critical Thinkers tier sub. Okay. Normally this just goes to the guests of the show. We don't normally give away lifetime subscriptions, but we're going to make an exception this time. So go to the Discord, go to the giveaways channel. and say, ready to hack on Adobe, and then paste in your link to your Intigriti profile, and you'll be entered in the raffle to win a lifetime Critical Thinkers tier subscription. This is like several thousand dollars worth of value. Okay, so definitely get on it. Um, all right, that's it. Congrats to Adobe on the shift, and let's get back to the show.
[00:01:41.75] - Joseph Thacker
up guys? This week in bug bounty, we've got something cool. Yes We Hack has released a solution to the ASLOT problem called Yes We Hack credits. So the way these credits work is everybody will start with a set number of credits. I think it's like 8. And then whenever you submit a vulnerability and it gets accepted, it automatically goes up by like 2 or 4. Oh yeah. So yeah, if a submitting report costs 2 credits and then the report is marked as accepted, the hunter would be awarded 4 credits because they would get their 2 credits back for the submission and then they would get 2 for it being accepted. So this is their kind of unique and pretty cool solution at YesWeHack to combat AI slop. And then, you know, as you submit more and more reports, you'll get so many credits that it won't matter, you know, as you get more and more reports accepted. And then if you report slop or you report spam, then you, you know, you'll slowly go down. So if it is a spam report, it's my— it's -2 times whatever the submission cost is. If it's invalid, it'll be -1 times the submission cost. And on every company's page, on their scope page here, it tells you the cost to submit reports to them. So, you know, companies can be a little bit more stringent or a little bit more lenient. And so anyways, pretty sweet, and I think you all will like it.
[00:02:54.93] - Vitor Falcao
Check it out. Yeah, well, we are here in Vegas, okay? We invaded one of the hotel rooms. I have a bunch of guys over there and they are talking whether they should not be talking. And, uh, we're just gonna have like the old school episode, uh, low quality image and everything. It's gonna be Amazing. Okay, what you have for us?
[00:03:16.37] - Brandyn Murtagh
We're on the road, we're slightly jet-lagged, we've got kitchen utensils to help us out, as you can probably see. But this is exactly the sort of content that we've all missed on Critical Thinking. So yeah, we're in, what, one day left of DEF CON now? You leave?
[00:03:31.24] - Vitor Falcao
Yeah, we have tomorrow. Like, I leave like 4 AM, guys, so I just want to, you know, go back. But I also want to do this. I'm exhausted. Everyone is exhausted. If you see this guy's face on the audience, they're like old dad over there, you know? Yeah.
[00:03:45.72] - Brandyn Murtagh
Yeah. Well, so let's get started. DEF CON so far. This is your first DEF CON, right?
[00:03:50.87] - Vitor Falcao
No, second.
[00:03:52.78] - Brandyn Murtagh
When? When did you last— when did—
[00:03:54.77] - Nick Copi
when was there last year?
[00:03:56.06] - Brandyn Murtagh
Last year, bro. Oh yeah, of course it was. Okay. What do you think of this one? Okay.
[00:03:59.84] - Vitor Falcao
I think this one has less people for sure. I don't know what is going on, but also amazing. I think I didn't go to any talk but mine. That's, uh, I don't have time for that. Like, it was insane, a lot on my plate, and that's Justin's fault, but that's fine. And dude, I think the quality of the talks are way better this year, at least for Bug Bounty Village. I mean, did you, did you get to watch any?
[00:04:26.01] - Brandyn Murtagh
Yeah, yeah, I saw Brumund's, James Kettle's. Um, there's a Gentiq AI one today which I caught part of. And there's also another one, Kashki poisoning. Oh, that was Roman's. And what was the other one?
[00:04:43.56] - Vitor Falcao
Did you mention the one by—
[00:04:44.83] - Brandyn Murtagh
oh, browser desync.
[00:04:48.12] - Nick Copi
Did you see that really good Kaido workshop today?
[00:04:51.23] - Brandyn Murtagh
And yours. Yeah, I did see that, but I didn't do the workshop.
[00:04:56.07] - Vitor Falcao
Okay, so basically, we had a lot of talks by critical thinkers and people around it. Did you mention the one by the Akamai, Ryan Barnard?
[00:05:04.42] - Brandyn Murtagh
Oh yeah, I've seen quite a few actually.
[00:05:06.33] - Vitor Falcao
Yeah, that's amazing. So I hope we can do faster releases on YouTube this time. I mean, Bug Bounty Village, because it took 10 months last time.
[00:05:16.43] - Brandyn Murtagh
Yeah, I mean, it was quite long, but I've spoken to a few people and there's a lot of research being published to personal blogs, which is a saving grace, which I'm looking forward to. But yeah, I mean, Shout out to Harley and all the guys and girls for sorting out Bug Bounty Village because it's a bit of a pillar now of DEF CON.
[00:05:35.47] - Vitor Falcao
And you know what's funny? If you catch me, grab me in person, he's such a different guy during the podcast. He's so serious, right?
[00:05:43.38] - Nick Copi
There's the classic Fav meme of the episode of, is bug bounty over? And his Twitter, his tweet was like, Geek versus locked in.
[00:05:55.32] - Brandyn Murtagh
Yeah.
[00:05:55.49] - Nick Copi
And it's just the, just, ah, Rezo, and then just the super stoic Brandon. We have the geeked Brandon and not the locked in Brandon.
[00:06:04.39] - Brandyn Murtagh
Yeah. But like, I purposely made sure that for this DEF CON, I had no plans, I had no commitments. I've been borderline uncontactable so I can just freestyle it, go to talks, network, speak to a lot of friends. And it has been great.
[00:06:19.66] - Vitor Falcao
That is totally what I'm gonna do next time.
[00:06:22.07] - Brandyn Murtagh
Yeah, that's what I mean. And this started for me at an event. So I collabed with Matt Brown. Lots of good hackers there. We had XSS Doctor. I'm trying to think.
[00:06:32.68] - Vitor Falcao
Okay, so we have you. You were in an event. Turbo was also in an event. So how did it go for you?
[00:06:41.63] - Nick Copi
Man, I was sad that I couldn't make it in person because I had flight issues. It felt like a sitcom. But without getting into that, the event was good. I definitely learned a lot. It was a very fun scope. There was a lot of JavaScript. So I had a lot of fun playing in the JavaScript, as I like to do, and popped a good number of bugs that I was pretty happy with.
[00:07:04.02] - Brandyn Murtagh
Any event takeaways? Like, so I try every event I do, even if it goes, doesn't go my way, or if it goes really well, I try to do it in Notion, of course.
[00:07:13.23] - Nick Copi
Yeah, yeah, definitely. I have a bad habit of bringing clients client-side bugs to server-side fights. So sometimes you really don't have a great feel for, especially if it's a program you haven't hacked on before, how they feel about certain impacts of client-side behaviors. You might have assumptions about their threat model, but they might just have assumed a lot of risk.
[00:07:34.87] - Vitor Falcao
Yeah.
[00:07:35.13] - Nick Copi
And so they might be aware that they have shortcomings that are kind of not something that they can really address. And so those kinds of findings, they just aren't as interested in, as opposed to some of the more patchable server-side behaviors versus just like, yeah, web browsers were a bad idea and it causes problems always.
[00:07:57.81] - Brandyn Murtagh
Yeah, no, that's fair enough. I feel like when you jump into an event on a target that you haven't looked at before, there's always like a period of trying to understand the threat model, jump in and understand what the team cares about, but you're in a live event, so you just want to get as many bugs out as possible.
[00:08:13.24] - Vitor Falcao
Yeah, and one extra thing is the event you were in is they used a hardware scope. So that was basically hardware hacking. How did it go for you?
[00:08:22.14] - Brandyn Murtagh
Yeah, really well.
[00:08:24.08] - Nick Copi
What?
[00:08:25.36] - Vitor Falcao
I was expecting the opposite.
[00:08:26.75] - Brandyn Murtagh
No, no, really well. Me and Matt Brown collabed. So we've been meaning to collab for ages, like for ages since I first met him at my first LAG in Scotland. We just randomly started chatting. Got on really well and always said we're going to collab. This hardware event came up and we committed to it. So his game plan was the whole time, he was like, I'm going to extract, dump the firmware, and just pass it to you and let you do your thing. It took me a couple of days to get warmed up and to understand the devices I was looking at. There was numerous in scope, but after that, it went really well. We chained a lot of nice things together. We also— I wanted to focus this event on, like, device-to-cloud pivots because given the threat model, given the target, given the devices, I thought that could be quite impactful. And I think it was. So we managed to get a few of them, had a lot of fun, and I learned a ton. And dude, XSS Doctor has been locked in. Like, I've never seen the guy move like this. Yeah.
[00:09:28.01] - Vitor Falcao
Okay. I saw what happened. I saw the whole Holy Cross surfing, he was like sharing with me and like, oh my God, this copy's hardware. What am I gonna do? I'm gonna do AI. And I'm like, yeah, go there and do it. And he even got a show and tell.
[00:09:41.67] - Brandyn Murtagh
Yeah.
[00:09:41.84] - Vitor Falcao
And it was so funny because he got the show and tell and he got to me and he's like, I don't understand the bug. I don't know. It's a critical, I reported it, they love it, but I don't understand the bug.
[00:09:51.09] - Brandyn Murtagh
Yeah.
[00:09:51.37] - Vitor Falcao
So he spent like a week learning about whatever he got. to do this, Chantal.
[00:09:57.16] - Brandyn Murtagh
That's what—
[00:09:57.45] - Vitor Falcao
that's like mind-blowing.
[00:09:59.10] - Brandyn Murtagh
So I would say it was home to own ask. Like, genuinely, like, seriously, it was really, really impressive. He was very happy with it. I think— I'm not sure if it's been paid out. I think he was very happy with it. But yeah, he's just been locked into hardware and like obsessed over like understanding UUP to like try and dump firmware. It's been interesting to watch because The guy has just been fixated. And I think XSS Doctor might start turning to hardware a bit more rather than client-side after this. Do you think?
[00:10:32.00] - Vitor Falcao
Yes.
[00:10:32.38] - Brandyn Murtagh
Yeah. Oh man, he has been loving it.
[00:10:34.30] - Nick Copi
What I heard from him was like before the event, like a month leading up, he was like practicing soldering every morning and it was so exciting for him because he finds it's all like a fresh green space for him to learn all this new stuff in. And he's like worried about being able to desolder things, right? Because he's only going to have like one device in the event and So to see that that actually went well, that rules, because I know he put like so much time into preparing for it.
[00:10:57.21] - Brandyn Murtagh
Yeah, yeah, he did. I also found out as well, we started talking about agents, as you do. Um, I have evals for my agents, whatever, to look at. When XSS Doctor makes a change to his prompts or agents, he manually watches the output of the agent.
[00:11:13.00] - Vitor Falcao
That's the way.
[00:11:14.14] - Brandyn Murtagh
Manually.
[00:11:14.78] - Vitor Falcao
Yeah.
[00:11:15.25] - Brandyn Murtagh
And then, uh, steers it from there. I think that's— it's impressive. But I'm not sure if I could sit there for a couple of hours whilst the loop completes. I'm not sure if I've got that in me.
[00:11:24.28] - Vitor Falcao
Oh, but let's do a quick break because do you know what is funny? We didn't introduce him.
[00:11:29.12] - Brandyn Murtagh
True. Oh.
[00:11:30.02] - Vitor Falcao
Yeah. Can you please do it?
[00:11:32.90] - Brandyn Murtagh
Turbo. I mean, what's there to say? The guy eats JavaScript sandbox boxes for breakfast and he eats more JavaScript for lunch and dinner. That's all you really need to say.
[00:11:42.76] - Vitor Falcao
Is it true that you once dreamed that you were in a JS sandbox?
[00:11:47.78] - Nick Copi
Okay, so that is true.
[00:11:48.61] - Brandyn Murtagh
I had, okay, but So, yeah.
[00:11:51.24] - Nick Copi
So, the night on the flight out to, or before I flew out to Vegas, I woke up at like 1:00 AM. You know, I had to wake up at 6:00 for my flight. I woke up from a nightmare that I was like HTML being injected into the DOM and I'm being blocked by the CSP and can't execute. It felt weird. Like, I don't know. It was, so, yeah, I still haven't got enough sleep since then. It's been a very Tiring Vegas, but that's, that's what I came into it with. And yeah, one day I'll get better.
[00:12:22.16] - Brandyn Murtagh
Yeah. So if you think you're a client-side guy, there are levels to the game and this man is right on top. I've never seen anything like it. But yeah, that's, that's kind of crazy. I'm gonna be honest, man.
[00:12:34.45] - Vitor Falcao
We got a crazy audience, by the way. We have Javox, we have Ads, uh, who is behind the cameras. We have— oh my God, we have PopSack. which is very active in the critical thinking community. We have Splinter, we have Sam, uh, Jakey, bro, and we have Justin here, but not Justin Gardner, another Justin. And, um, amazing, amazing guys. I think we could do a rotation. Do— what do we— what do you want to do?
[00:12:57.72] - Brandyn Murtagh
Well, I'll tell you what, you boys both done talks this event. Yeah, give the audience a brief overview as to what you've done, what you spoke about. I mean, some of you have done multiple.
[00:13:08.28] - Nick Copi
Yeah, so I did a workshop focused on hacking VS Code extensions. So it was specifically focused on the more juicy VS Code extensions that are set to activate without workspace trust. So it's a lot more clear of a threat model there, and it's a lot easier to argue for your bugs. So it was some slides going through the context, explaining how to debug these, and then a vibe-coded Copilot extension, which is like Copilot, pilot, but there's no one behind the wheel and it just does stuff like lead Darcy. And so it had all kinds of bugs in it and we kind of walked through what those would look like. My understanding is that there will be a CTBB exclusive version of that given, I think, Boss told me that I should, I think I agreed to do that after DEF CON.
[00:14:00.34] - Ads Dawson
Yeah.
[00:14:00.75] - Nick Copi
So that'll probably be coming eventually within the next couple months. But it was a, Fun workshop, and it was fun live debugging, uh, some of the reproduction of some of the bugs on there because it was mostly Vibe code and I didn't even know how it worked. Uh, so getting to show off the real process of actually debugging it live and popping the RCE was, I think, entertaining. And I think people got value from that aspect of it because it definitely is kind of a different ecosystem than some people are used to working in.
[00:14:30.57] - Brandyn Murtagh
Yeah, and the attack surface is nice as well if you can unlock that. and you know what to look for, you can get some pretty nice bugs. I've seen some. And in terms of actual talks you attended, anything stand out? Did you attend any interesting? Anything get the juices flowing?
[00:14:45.85] - Nick Copi
I always love the Unicode talk. Like, this version.
[00:14:53.77] - Vitor Falcao
By Rand Barker? Yeah.
[00:14:55.63] - Nick Copi
And Angela Hacker. Yeah. Like, it was every single, like, Each item in that is just, like, such a juicy nugget of, like, but where could I apply this and how could I take this further? Like, each item there, it feels like I want to turn each one of these into a concrete bug in a real target because they're all such, like, interesting minor discrepancies that can lead to such major impact.
[00:15:18.28] - Brandyn Murtagh
Yeah. It was nice as well seeing it from their perspective because obviously they're on the other side. And even though we know these things intuitively, seeing their thought process, their threat model about how they reverse engineer things. Like one of the ones with the, um, when he, uh, decoded like the 2 backticks and it's just like a malware embedded in some JavaScript library. So yeah, I think that might also be coming to Critical Thinking as an exclusive in the future.
[00:15:46.65] - Vitor Falcao
Yeah.
[00:15:47.30] - Brandyn Murtagh
Um, so look out for that as well, guys. But what about yourself, boss? You've done more than one, I believe. I believe. Did you not?
[00:15:53.08] - Vitor Falcao
Yeah, I did a panel too. And this— that's Vegas mode. Yeah. Exclusive talks. I'm gonna make them come all cheap, record as many of them as we can. And yeah, that's gonna be amazing. You're gonna do it. You don't have an option, but I'm gonna let you rest a little bit from Vegas. Okay. So yes, I did 2 talks. One was with Emil. Emil is from Kaido. We did a Kaido plus AI talk, but We didn't want to focus on Kaido. That's not the point. We want to help people desopify their workflows by connecting AI to Kaido and showing how that works and how creative you can get. You can have AI building custom plugins for a custom behavior you have in a program. And I did it. I did it for Protobuf in Google. And dude, I gave AI, I think I gave, it was Codex, such a stupid prompt. And the output was amazing. It has like a full AI. It called it RPC mapper. You have all the function and inputs and outputs and everything. I was like, what? Like, I didn't expect my talk to be so good at this point. Like, I can't believe that that worked so well. Yeah. And then same day, which was today, we had a panel. It was hosted by Nehan Saikban. And it was me, Eds, and some Joey Mallow. Mike and Dustin. We are in the BT6 team and we talked a lot about AI. I think the name was BOTS, Bounties and Bullshit or some kind of thing like that. And it was like a crazy amazing talk. We learned a lot of it. You were there. What did you think?
[00:17:30.00] - Nick Copi
The questions were really good and the answers were even better. It was surprising how intuitive some of the answers were, but I think what really stuck out to me was such complicated questions with such nuanced answers that are explained in a way that's very easy to understand. I feel like that was a lot of the value. Those BT6 guys are so knowledgeable about that stuff and they just have the hands-on experience to back— when they're asked a question about this, they're all thinking of some concrete example in their mind of when they've performed that kind of exploitation. And yeah, so I liked the fact that the questions were super relevant and that the answers were very dialed in and based on concrete hands-on experience.
[00:18:16.45] - Brandyn Murtagh
Yeah, nice.
[00:18:17.09] - Vitor Falcao
Yeah, shout out to Ben for making such a good host. He was amazing. He had a list of questions he showed us beforehand so we could have some small preparation and everything was amazing.
[00:18:26.93] - Brandyn Murtagh
Yeah. Wasn't the panel like an hour and a half long as well?
[00:18:30.30] - Vitor Falcao
An hour and a half. At the end I was like, You know, Vegas dry. My, my mouth was like hurting at a point. I needed water, but there was no water close to us. But worth it. Worth it.
[00:18:42.00] - Brandyn Murtagh
Yeah. Yeah. So in terms of other talks, you guys are both— are you gonna be here at all for tomorrow or you, or you've like—
[00:18:48.75] - Nick Copi
I fly out at noon, so I'm leaving. I'm probably waking up at 7-ish and going to the airport. So no, I, I'm missing closing ceremony and I'm missing Monkey giving Cactus's talk.
[00:19:01.14] - Brandyn Murtagh
Which, that should be good.
[00:19:02.35] - Nick Copi
Yeah, he told me some of his preparations he's done for it.
[00:19:05.77] - Brandyn Murtagh
What was the title? Sorry, uh, can you remember?
[00:19:09.22] - Nick Copi
I have no idea, but I know that, uh, he has a cactus that he has inserted a device into to make voice lines that he had Hactus record explaining why he couldn't be there. So it's gonna be— it's a Hactus talk, so it'll be good. Like, I don't know, but I'm gonna miss that.
[00:19:24.97] - Brandyn Murtagh
Yeah, okay, I'll make sure to— I'll make sure to Get that, feed it back to the team because yeah, that's gonna be good. I think it was on hacking AI. It was hacking AI and the other way around, hacking with AI. I think that was the talk.
[00:19:43.39] - Vitor Falcao
By the way, Kieran Munke, he should be here, but he's also exhausted. I'm sending him a message. He stopped replying like, dude, this guy crashed out.
[00:19:51.05] - Brandyn Murtagh
So yeah, it's a bit— We are recording this really late, by the way, for listeners. So please be patient with us if we're not making sense. I promise you.
[00:19:57.90] - Vitor Falcao
Yeah, yeah, I got— that's internal joke, don't do that. I'm gonna wake up in like a few hours to go to the airport. So, uh, we're doing that for you guys.
[00:20:08.88] - Brandyn Murtagh
Yes. So other things, did anyone catch James Kettle's talk this year? We have to—
[00:20:14.34] - Vitor Falcao
No, but that's, that's so hard because we have so many things happening at the same time there.
[00:20:18.84] - Brandyn Murtagh
Yeah, there's a lot of clashes. James Kittles' talk, he covered a lot of his new research and also his methodology and open-sourced, actually, the tool that he made of vulnerability research on request smuggling variants and his new tool. I think it's called HTTP Terminator. Okay.
[00:20:39.67] - Vitor Falcao
So the question in the title was like, can AI make novel research?
[00:20:43.59] - Nick Copi
Yes.
[00:20:44.42] - Vitor Falcao
So the answer is yes.
[00:20:45.44] - Brandyn Murtagh
Yeah. It was a lot of human in the loop. He had to— the talk was really good. The blog post is out now, by the way, for everyone listening. He had to make a lot of iterations because some of his harnesses were actually filtering out, was too restrictive, and filtering out a lot of interesting behaviors. I mean, it's James Kettle. The guy sat on so much gold, it's just insane. But yeah, honestly, really good talk. The repo is open source. All of his prompts are open source. The methodology is also open source. It's all detailed in the blog post, so I recommend checking it out. Did out. Did
[00:21:20.96] - Vitor Falcao
out. Did out. Did you catch it?
[00:21:21.90] - Nick Copi
No, I haven't even— I haven't had time to even read the blog post yet, which—
[00:21:27.22] - Brandyn Murtagh
Yeah, dude, it's a banger. I I
[00:21:30.68] - Vitor Falcao
I I was considering like literally printing the research to read it in the airplane and everyone like was like making fun of me. I was like, guys, that's just paper and ink, like old school.
[00:21:39.70] - Brandyn Murtagh
You could also save as HTML like a normal person.
[00:21:43.49] - Vitor Falcao
No, man, I don't want screams on the airplane, you know, it's a red-eye flight. I just want to, you know, sleep and things like that.
[00:21:49.99] - Brandyn Murtagh
But yeah, I do highly recommend. Um, other than that, recent bugs, what have we got? Anything good from events? Anything notable or even really comically bad that you'd like to talk about?
[00:22:03.25] - Nick Copi
Recent? Uh, I have a funny bug from a while ago, but we'll say recent bugs. So Well, I don't know. I don't want to talk about this one because it's not patched.
[00:22:12.08] - Brandyn Murtagh
Okay.
[00:22:13.04] - Nick Copi
The long and short of it was query param injection in an API request from the document.location.pathname or whatever. Let me get an ampersand in and affect a GET request made by some component on the page that was able to lead to XSS via a chain that I can't really get into. I do have just a classic bug story.
[00:22:39.92] - Brandyn Murtagh
Let's hear it.
[00:22:40.94] - Nick Copi
So, this was in a chat application. So, it was an XSS bug in the rich poll functionality or something where when you send a message, it's defined as some JSON body. And so, the poll's defined that way. And one of the things that supported— so, it's a React app. It has some props component and props component wrapper. This is in something that no longer exists, but I can't get them to disclose it because I can't get them to respond. So unfortunately, I can't say the target, but you could put in arbitrary props that got set on a React component. So you could do a dangerouslySetInnerHTML and have an __html and have arbitrary HTML there.
[00:23:27.78] - Ads Dawson
Interesting.
[00:23:28.84] - Nick Copi
So you have stored XSS via a chat message that's like wormable. They didn't really pay those very well, which is like absolute nonsense. So I decided to escalate it via their Electron app.
[00:23:41.76] - Brandyn Murtagh
Okay.
[00:23:42.52] - Nick Copi
So I'd already like shelled it with a past XSS and it was like with a Chrome bug and they'd updated their Chrome and I was like, oh man. So I'd done a pretty deep audit of the like Electron IPC handler stuff. that was supported by it. And I couldn't find any like free RCE escalations via like file writes or something. But I did find a way to persist the XSS. So there was an IPC method you could call that would like set the default page that the app would open up to. And you could just point that at a public message that had the XSS payload. So every time they closed it, it would pop that XSS, open a hidden window, because there was an IPC call that would open a browser window, persist the XSS there, navigate back to the main app. And so they couldn't even tell that they'd been XSSed and that would persist it. And from there, via that IPC listener, I could get processes running. I could get screenshots of desktops and screenshots of every single process. So I built this whole, and this was pre-AI, so I couldn't just vibe code this. This was a couple years ago, maybe more, but built this whole spyware system. So you get sent a message and this is wormable. You get sent a message, it adds that to your config, sets that up. You don't even realize. And now your whole process list is being leaked. Your whole screens are being leaked and like updated every 60 seconds. You could select a process and get a screenshot of just like the window. And then I also had an eval.js thing that would talk to it over a WebSocket. and let your own JS authenticate it as the victim. Yeah, they paid it out as like a lower on their high-end bounty.
[00:25:27.44] - Brandyn Murtagh
Was this in a live event or was this—
[00:25:29.00] - Nick Copi
No, this was, this was a public program.
[00:25:32.71] - Vitor Falcao
Wow.
[00:25:33.02] - Brandyn Murtagh
Okay. That's like some NSA-level spyware right there.
[00:25:36.54] - Nick Copi
Yeah, no, it was a lot of fun and that's why I wanted to talk about that one.
[00:25:40.84] - Brandyn Murtagh
Okay.
[00:25:41.41] - Nick Copi
Especially because it's in a dead application now like that.
[00:25:47.51] - Vitor Falcao
They—
[00:25:47.92] - Nick Copi
that project got canned.
[00:25:49.22] - Brandyn Murtagh
Okay, fair enough.
[00:25:50.16] - Nick Copi
Yeah, but unfortunately it's not disclosed. I really want to get that one disclosed because I feel like that would be a real fun one to write up. Yeah, I know, man.
[00:25:58.25] - Brandyn Murtagh
Yeah, yeah, yeah, very nice.
[00:26:00.57] - Nick Copi
Oh well.
[00:26:01.15] - Brandyn Murtagh
What about you, Gus?
[00:26:02.98] - Vitor Falcao
Okay, since he's going like spider mode, I have one. I'm not gonna give that many details, like, uh, it's not that complex, but I've been, uh, exploring some applications that by default you want to share camera, geolocation, microphone, et cetera, because that's part of the features of the website. So I've been finding some crazy vulnerabilities recently that I can make you click the link of one of those websites. And just by clicking on those, let's just use an example. Let's say it's google.com. It's not google.com, but whatever. Let's say when you are in google.com, you always allow Allow your camera and microphone. So I have a way, I've been finding ways to steal, to hijack your camera and microphone in a way that you click a link, when the page opens, it starts sending all your camera image, microphone, and stuff to me. And they have, like everyone has been paying it as at least a high or critical. So I am farming it for a while. In 6 months I release the research because I'm gonna be tired of finding those.
[00:27:07.11] - Nick Copi
And it's, Not a browser bug?
[00:27:08.77] - Vitor Falcao
It is a— no, it's not a zero-day on Chrome.
[00:27:11.42] - Brandyn Murtagh
No, no, no, no.
[00:27:12.20] - Vitor Falcao
It's basically a developer miss— you know when they had the postMessage thing?
[00:27:16.29] - Nick Copi
I have some ideas in my head of how this might work.
[00:27:18.70] - Vitor Falcao
No, get out. Come on. No, it's my bounces. Yeah. So basically, you know postMessages, they were always there. They're not a zero-day, but no one were— the people were not using them as they should be used. They were not like checking origins or anything like that. Then Franz Rosen get there and like, That's the kind of thing. So when I get tired of looking for those, since I still want to make a safer environment for everyone, I'm going to publish it and you guys read it, make a skill with AI and just plop it everywhere or something like that. Yeah.
[00:27:51.85] - Brandyn Murtagh
Wow. Yeah. Nice. I mean, so in this event, as I said, I focused on some device-to-cloud pivots and although I can't directly talk about a lot of the stuff. The process behind it, it was interesting. So obviously, understanding how a device talks back to the cloud and how that whole process happens, reverse engineering that and understanding and doing the token shuffle where you understand, okay, I've got a token with a claim in here and—
[00:28:23.88] - Vitor Falcao
Yeah.
[00:28:25.80] - Brandyn Murtagh
Tracing the flow from a device had its own problems and was a lot more difficult because I didn't have root on the device. So I was working from a dev shell that was in this ecosystem. Yeah, I need to be careful what I say here. I was working from a less privileged context. So understanding where, at what point tokens are exchanged at, understanding what claims that each token has, and understanding individual services that they communicate with as well. I actually had quite a nice one where I could do a token shuffle, send it to, like, a credentials endpoint, and it would return back a blob. You decode the blob, and it was actually some temporary AWS credentials. Yeah. Using that, thankfully, I had AI on my side.
[00:29:18.06] - Ads Dawson
Yeah.
[00:29:18.25] - Brandyn Murtagh
But to understand some context, I didn't want to use these temporary credentials. For context, everyone, I've built a lot of tooling around brute-forcing cloud permissions to understand what context I'm operating on when I'm in these situations, because I often end up in these situations when I'm hunting. I didn't want to do that. Luckily, my friend Codex went through all the binaries.
[00:29:41.25] - Nick Copi
Yes.
[00:29:42.13] - Brandyn Murtagh
And extracted some permissions names and a lot of the things it was interacting with. And I'd done lovely little scripts to see what I could hit, and I could disclose a lot of information, shall we say, from a secrets manager that one of the devices used, which was shared across the whole fleet. So it wasn't just scoped to that device. It was originally, but I'd done a token shuffle to get the AWS credentials and then pivot from there. So I found 2 of those, which is quite nice. We'll see how they go. But yeah, the token shuffle and just understanding the auths is Yeah, very impactful.
[00:30:21.75] - Nick Copi
That sounds good, Chris.
[00:30:23.35] - Brandyn Murtagh
We'll see. We'll see. We will see.
[00:30:26.16] - Nick Copi
Well, I guess it depends what the secrets do.
[00:30:27.91] - Brandyn Murtagh
Exactly. But yeah, that was takeaway for the listeners. Understanding and reversing your steps on how these tokens are generated and doing these, I mean, I call them a token shuffle. What would you call that process?
[00:30:43.21] - Nick Copi
So to me, what stands out there is, and, you know, if you're in situations where you end up with embedded AWS credentials as part of the design of the system and you want to— whenever I get those, I'm not inclined to like run any of those like brute forcers. I'm always like, do we have access to number one, the design of the system? Like, what are— why does the— why do these exist? Because obviously they need to exist for some reason. Then 2, if there's binaries, if there's source code of any kind, if there's what— I always go to that first before I even think of brute forcing those because that usually answers the question of like, Why do— what are these creds even for, man? So I think that right there is a good takeaway of like, someone might just run a grep, get those creds and not think to actually look at why do—
[00:31:31.93] - Brandyn Murtagh
The context. Right.
[00:31:32.73] - Nick Copi
Why do these need to exist? That'll probably answer the question. Whereas a lot of those, I've just not had good results with a lot of those brute forcers, especially if it's like, it can read from this one DynamoDB server that's shared for— it's like, you're not going to find that permission because you're not going to be Testing against the DynamoDB server that's mentioned in some embedded thing, for example.
[00:31:53.86] - Brandyn Murtagh
Yeah, and that is a problem that I had creating some of this tooling, because it's like, I can get a rough idea for permissions, but when you start to query a permission that requires an ID, or like an actual resource ARN, for example, then you're just never going to hit that. So luckily, extracted it from the context that we were working in, and went from there. But I've never, this was the first time I was in the context of trying to do that from a device. So, like, understanding the threat model of, okay, this should be like this, whereas this actually shouldn't. This seems like it's tenant-wide and loosely permissioned.
[00:32:26.44] - Vitor Falcao
But yeah, isn't it, like, part of your game always going for authentication stuff? Because that's kind of authentication and authorization. You always do that.
[00:32:35.70] - Brandyn Murtagh
Like, I do, I do. I actually do. I'm not sure why. I just seem to be lured towards that. I've set up like many of my own custom SSO providers for previous events. Yeah. And I have like key instances.
[00:32:48.58] - Nick Copi
Sysadmin Brandon mode.
[00:32:50.36] - Brandyn Murtagh
Spending so much time.
[00:32:51.81] - Nick Copi
7 days of an event just setting up infra and then—
[00:32:55.81] - Brandyn Murtagh
Yeah. Ads is behind the camera right now. That was a previous event.
[00:32:59.27] - Vitor Falcao
Wait, wait, wait. We're doing that in Vegas for a reason. Come here, Ads. Come here.
[00:33:02.39] - Brandyn Murtagh
Come on. Come on, Ads.
[00:33:04.33] - Vitor Falcao
Yeah, that works. Yeah, take your time, dude.
[00:33:09.50] - Brandyn Murtagh
Yeah, there we go. Come on. Thank you, everyone.
[00:33:12.34] - Vitor Falcao
Thank you.
[00:33:12.98] - Ads Dawson
There you go.
[00:33:13.39] - Brandyn Murtagh
That was a bad idea.
[00:33:14.15] - Vitor Falcao
Okay, so quick intro. Ads is one of the best hackers, you know. He was in one of the latest episodes, right? He does a lot of AI stuff. He was with me in the BT6 panel. We do a lot of AI red teaming, things like that. I don't need— anything you wanna say?
[00:33:32.44] - Ads Dawson
you for sharing your kitchenware with me.
[00:33:36.20] - Vitor Falcao
Yeah, wait, if you guys can't see, that's the— that is that. Okay.
[00:33:42.69] - Brandyn Murtagh
So, for context for listeners, why I get called a sysadmin, because I somehow seem to find myself in scenarios where I spend days solely on configuration. Me and Az were in an event where I spent, what, 4 or 5 days of certain configuration for a certain ecosystem, which we can't say, but if you knew, you would understand how painful it was, just so we could hack. And it's become a bit of a running joke because it seemed to have so much setup. It was a beautiful setup, to be fair.
[00:34:13.73] - Brandyn Murtagh
So, you've also done a couple of talks. Hold on, you've had a crazy run this week. You've had so much on. What talks have you done? What did you like? didn't you like?
[00:34:25.32] - Ads Dawson
didn't enjoy any of it until I finished it. it.
[00:34:27.15] - Vitor Falcao
it. it. Yeah, that's fine. I'm seeing the thing go red on the computer, so yeah, you don't need to beat the horse. Okay.
[00:34:34.63] - Ads Dawson
not used to this kind of equipment.
[00:34:36.92] - Brandyn Murtagh
right. No, right. It catches your attention.
[00:34:38.48] - Vitor Falcao
High quality equipment shipped very fast by Amazon.
[00:34:43.34] - Ads Dawson
start of the week, as part of BT6, we did embodied reasoning, like hardware hacking on Which is those little robot dogs.
[00:34:55.90] - Vitor Falcao
Yeah.
[00:34:56.88] - Ads Dawson
was like super fun. It was like prompt injection, you know, like make the dog like attack a human kind of thing. Then we did some like binary exploitation or like some zero days. So there's some like, you know, I'll be very careful what I'm saying actually. I think I saw from the— Yeah, yeah.
[00:35:13.73] - Vitor Falcao
It's recorded, by the way. If you make a mistake, people will hear it.
[00:35:16.88] - Ads Dawson
There's some like really wormable zero days where you can effectively the dogs with one dog. It's really bad. But yeah, so that was fantastic. And then, yeah, I did a red team panel with Ben. Shout out to Mr. NahamSec. Yep.
[00:35:33.09] - Nick Copi
Yesterday.
[00:35:33.86] - Ads Dawson
was great fun. It was pretty much along the lines of using agents for offensive AI.
[00:35:41.17] - Ads Dawson
then, yeah, we had the panel today with Mr. NahamSec again, which was awesome. And shout out to TACSEC. We did Exfil Everything, which is basically some of the bugs that we found on Mela in Taipei.
[00:35:57.46] - Vitor Falcao
And a big shout out to the Bug Bounty Village because I wasn't expecting so many people. They were like making a huge line and they were like guiding them and flashing the room and doing all that kind of stuff. I hope we keep getting more and more space every year, guys, because we need it. Yeah, yeah, yeah.
[00:36:15.63] - Brandyn Murtagh
The community seems to be ever-growing. Lots of fresh research from everyone this year, which is really good. And what I would say, I, I think I was speaking to some of you earlier about this, um, the ROI for me from these events of just like the ideas, the fresh research, seeing your friends that you only get to see once a year. I mean, if you're unsure about going to DEF CON or getting involved in conferences, I most definitely recommend it wholeheartedly. I mean, it's no secret that bug bounty, the wait times are killing people. Morale's been slightly lower than usual. Going to these events just reignites that fire again, gets you thinking about bugs to look for, fresh research. I cannot recommend it enough. I mean, I wasn't expecting to come to this and get that from it, but it has definitely done a lot for me.
[00:37:05.44] - Vitor Falcao
Yeah, there are people around us popping bugs right now. I think there is someone popping a bug right over here because it's very quick.
[00:37:13.65] - Brandyn Murtagh
Just out of frame to the side.
[00:37:15.13] - Vitor Falcao
Yeah. So yeah, we got here and usually when I'm in Vegas, it's impossible for me to hack because I need my setup, my focus and everything. But these guys are insane. They're like, we're gonna pop a bug and they just do it. And it's like critical.
[00:37:30.78] - Brandyn Murtagh
I feel like that's what it's like Being with the community though, like, there's so many ideas. Like, even outside of Bug Bounty Village today, I just saw a fleet of laptops and people collabing on, like, uh, on the— And you, even before your talk, you were meant to be preparing your slides and you were popping bugs. It was so much more fun though. Yeah, even this guy was popping bugs before his talk. I saw it with my own eyes.
[00:37:51.55] - Vitor Falcao
By the way, that reminds me that we had— I lost it. I don't know if someone went to the, uh, they call it, uh, the SLOP which the AI slopped a bunch of slides. They didn't see what, like, go to Claude and make slides about XYZ, and they don't see what the slides are about and they have to make presentations about the subject. That was—
[00:38:11.92] - Brandyn Murtagh
Wait, that was a thing?
[00:38:12.80] - Vitor Falcao
Yeah, that was a thing. When was it? Yesterday? Yes, it was Friday night. Yeah.
[00:38:18.67] - Nick Copi
It was Australians.
[00:38:20.17] - Vitor Falcao
Australians? Wait, what do you mean? The Australians were the organizers of the— yeah, okay. Yeah, those kangaroos, you know, they're all upside down.
[00:38:29.80] - Brandyn Murtagh
Yeah.
[00:38:30.44] - Vitor Falcao
But it was amazing. I love those guys. And yeah, we had that and they had like good questions and everything. So we have all the kind of stuff happening at the same time at DEF CON. And I think missing the talk is pretty much okay. I want to go there and root for my friends, but it's going to be on YouTube later too. So if you come to DEF CON, if you never did it, Don't worry, you're gonna get here, you're gonna get overwhelmed like I am right now, even though it's my second time. I think we never learn how to deal with that. And yeah, just go with the flow. I think that's been working pretty well.
[00:39:08.42] - Brandyn Murtagh
Yeah, I would say my schedule, I missed most of the talks I wanted to go to. The app that's used for a lot of conferences just wasn't working, it bugged on me. Regardless, I still got to see a lot of good talks, made a lot of good relationships with researchers this time, networked a lot. I mean, yeah, it's a win-win for me.
[00:39:27.28] - Vitor Falcao
We have the HackerOne people, we have the programs, we have like Amazon TikTok, Shopify, who else? We have so many of them, it's amazing to talk to them.
[00:39:37.15] - Ads Dawson
so Brandon actually missed the HackerOne event because he slept in the whole time. Oh yeah, so I do this every year. I've done this every year. I've been to DEF CON or even when I'm abroad, I go for a 20-minute nap and I wake up 9 to 10 hours later.
[00:39:51.78] - Vitor Falcao
That's true.
[00:39:52.34] - Brandyn Murtagh
Last year I checked my phone, it was Justin, " Where are you? Where are you? We're meant to go for dinner." Slept through the whole thing. So be prepared for that if you're like traveling quite far like me. Right now my laptop is actually 5 in the morning and we're doing a CTBB episode. So yeah, it's quite taxing on make dinner plans with
[00:40:12.13] - Ads Dawson
make dinner plans with Gr3pme. Yeah,
[00:40:13.44] - Brandyn Murtagh
Yeah, don't make any plans. It just usually won't work very well.
[00:40:17.34] - Ads Dawson
one thing I will actually, I'm very excited about. So I was speaking to Mr. Hayes, the god, Gareth Hayes, and he gave me a copy of his book. I've had the digital one for ages.
[00:40:29.59] - Vitor Falcao
JavaScript for—
[00:40:30.63] - Ads Dawson
yeah, the JavaScript book. It's a really great book, but he's actually put a really nice payload in it, which he has not disclosed, and he said it 100% works. So I'm very excited.
[00:40:39.59] - Brandyn Murtagh
you got said book on you?
[00:40:41.25] - Ads Dawson
No, it's in my hotel room.
[00:40:42.59] - Brandyn Murtagh
all right, no worries.
[00:40:43.65] - Ads Dawson
It's in my safe.
[00:40:44.63] - Brandyn Murtagh
is this a new version of it?
[00:40:46.19] - Ads Dawson
Uh, no, it is— I, uh, they had a bunch of copies.
[00:40:49.26] - Brandyn Murtagh
wow. Yeah, him and, uh, James, I spoke to him as I was collecting my badge, sung a lot of praise for the CTTB. It's good research. So yeah, that was nice to hear from those 2. But yeah, I think that's just about everything, guys. Anyone got anything else?
[00:41:05.01] - Ads Dawson
no, not really. No, just, I, I like encouraging people to come to DEF CON. I've met a bunch of dudes here and, you know, proud to call you all friends. You guys rock. Um,
[00:41:15.17] - Ads Dawson
Yeah, good times.
[00:41:17.01] - Brandyn Murtagh
All right, well, that is a wrap, everyone. Peace.
[00:41:19.55] - Ads Dawson
And that's a wrap on this episode of Critical Thinking. Thanks so much for watching to the end, y'all. If you want more Critical Thinking content, uh, or if you want to support worth the show, head over to ctbv.show/discord. You can hop in the community. There's lots of great high-level hacking discussion happening there on top of masterclasses, hackalongs, exclusive content, and a full-time hunters guild if you're a full-time hunter. It's a great time. Trust me. All right. I'll see you there.
Apple Podcasts
Spotify
Castro
RSS Feed
YouTube